Yixin Liu;Shiyuan Li;Yu Zheng;Qingfeng Chen;Chengqi Zhang;Philip S. Yu;Shirui Pan
{"title":"From Few-Shot to Zero-Shot: Towards Generalist Graph Anomaly Detection","authors":"Yixin Liu;Shiyuan Li;Yu Zheng;Qingfeng Chen;Chengqi Zhang;Philip S. Yu;Shirui Pan","doi":"10.1109/TKDE.2026.3691902","DOIUrl":null,"url":null,"abstract":"Graph anomaly detection (GAD) is critical for identifying abnormal nodes in graph-structured data from diverse domains, including cybersecurity and social networks. The existing GAD methods often focus on the learning paradigms of “one-model-for-one-dataset”, requiring dataset-specific training for each dataset to achieve optimal performance. However, this paradigm suffers from limitations, such as high computational and data costs, limited generalization and transferability to new datasets, and challenges in privacy-sensitive scenarios where access to full datasets or sufficient labels is restricted. To address these limitations, we propose a novel generalist GAD paradigm that aims to develop a unified model capable of detecting anomalies on multiple unseen datasets without retraining/fine-tuning or customization. To this end, we propose a few-shot generalist GAD method with three key designs, namely feature <u>A</u>lignment, a <u>R</u>esidual encoder, and in-<u>C</u>ontext learning, abbreviated as ARC. As a generalist approach, ARC only requires a few labeled normal samples during prediction on any unseen graphs. Specifically, ARC consists of three modules: a feature <u>A</u>lignment module to unify and align features across datasets, a <u>R</u>esidual graph encoder to capture dataset-agnostic anomaly representations, and a cross-attentive in-<u>C</u>ontext learning module to score anomalies using few-shot normal context. Building on ARC, we further introduce ARC<inline-formula><tex-math>$_{\\mathrm{zero}}$</tex-math></inline-formula> for the zero-shot generalist GAD setting, which selects representative pseudo-normal nodes via a pseudo-context mechanism and thus enables fully label-free inference on unseen datasets. Experiments on 17 real-world datasets demonstrate that ARC and ARC<inline-formula><tex-math>$_{\\mathrm{zero}}$</tex-math></inline-formula> effectively detect anomalies, exhibit strong generalization ability, and perform efficiently under few-shot and zero-shot settings.","PeriodicalId":13496,"journal":{"name":"IEEE Transactions on Knowledge and Data Engineering","volume":"38 7","pages":"4357-4372"},"PeriodicalIF":11.6000,"publicationDate":"2026-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Knowledge and Data Engineering","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/11514102/","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2026/3/11 0:00:00","PubModel":"Epub","JCR":"Q1","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
引用次数: 0
Abstract
Graph anomaly detection (GAD) is critical for identifying abnormal nodes in graph-structured data from diverse domains, including cybersecurity and social networks. The existing GAD methods often focus on the learning paradigms of “one-model-for-one-dataset”, requiring dataset-specific training for each dataset to achieve optimal performance. However, this paradigm suffers from limitations, such as high computational and data costs, limited generalization and transferability to new datasets, and challenges in privacy-sensitive scenarios where access to full datasets or sufficient labels is restricted. To address these limitations, we propose a novel generalist GAD paradigm that aims to develop a unified model capable of detecting anomalies on multiple unseen datasets without retraining/fine-tuning or customization. To this end, we propose a few-shot generalist GAD method with three key designs, namely feature Alignment, a Residual encoder, and in-Context learning, abbreviated as ARC. As a generalist approach, ARC only requires a few labeled normal samples during prediction on any unseen graphs. Specifically, ARC consists of three modules: a feature Alignment module to unify and align features across datasets, a Residual graph encoder to capture dataset-agnostic anomaly representations, and a cross-attentive in-Context learning module to score anomalies using few-shot normal context. Building on ARC, we further introduce ARC$_{\mathrm{zero}}$ for the zero-shot generalist GAD setting, which selects representative pseudo-normal nodes via a pseudo-context mechanism and thus enables fully label-free inference on unseen datasets. Experiments on 17 real-world datasets demonstrate that ARC and ARC$_{\mathrm{zero}}$ effectively detect anomalies, exhibit strong generalization ability, and perform efficiently under few-shot and zero-shot settings.
期刊介绍:
The IEEE Transactions on Knowledge and Data Engineering encompasses knowledge and data engineering aspects within computer science, artificial intelligence, electrical engineering, computer engineering, and related fields. It provides an interdisciplinary platform for disseminating new developments in knowledge and data engineering and explores the practicality of these concepts in both hardware and software. Specific areas covered include knowledge-based and expert systems, AI techniques for knowledge and data management, tools, and methodologies, distributed processing, real-time systems, architectures, data management practices, database design, query languages, security, fault tolerance, statistical databases, algorithms, performance evaluation, and applications.